Code Injection Vulnerability in dot-access by ntharim
CVE-2026-107700
9.3CRITICAL
What is CVE-2026-107700?
The dot-access package, versions 0.0.3 through 1.0.0, exposes a serious code injection vulnerability that can be exploited by remote attackers. By providing specially crafted paths to the get() function, an attacker can leverage JavaScript execution capabilities inherent in Node.js. This vulnerability occurs because the injected paths are concatenated into a new Function body in the index.js file, enabling access to constructor.constructor, which can lead to the execution of arbitrary operating system commands within the Node.js process. Users of the affected versions are strongly encouraged to update to the latest version to mitigate the risk associated with this issue.
Affected Version(s)
dot-access 0.0.3 <= 1.0.0
